CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102410  CVE-2017-5590  Candidate  An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for ChatSecure (3.2.0 - 4.0.0; only iOS) and Zom (all versions up to 1.0.11; only iOS).  Assigned (20170125)  None (candidate not yet proposed)    View
37130  CVE-2008-7013  Candidate  NetService.dll in Baidu Hi IM allows remote servers to cause a denial of service (client crash) via a crafted login response that triggers a divide-by-zero error.  Assigned (20090818)  None (candidate not yet proposed)    View
102666  CVE-2017-5846  Candidate  The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors related to the number of languages in a video file.  Assigned (20170201)  None (candidate not yet proposed)    View
37386  CVE-2008-7269  Candidate  Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the forward parameter in a logout action.  Assigned (20101201)  None (candidate not yet proposed)    View
102922  CVE-2017-6102  Candidate  Persistent XSS in wordpress plugin rockhoist-badges v1.2.2.  Assigned (20170221)  None (candidate not yet proposed)    View

Page 855 of 20943, showing 5 records out of 104715 total, starting on record 4271, ending on 4275

Actions